It has a clear MIT license, tests, documentation, and a recently active two-person contributor base. Packagist abandonment and an archived repository make this release unsuitable for a new dependency.
18%
Total Score
100
50
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct maintenance warning and outweighs the otherwise healthy package metadata.
The latest registry release was published in August 2022, with no releases in the last 12 months. That long release gap raises abandonment risk for a dependency.
The linked source repository is archived, which strongly indicates that normal future maintenance is not expected. Recent pushes do not compensate for the repository's archived status.
Composer build tooling is present, but no security scanning tooling was detected. This is a minor hygiene gap rather than a primary adoption blocker.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This adds a modest transparency concern alongside the stronger maintenance warnings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hampel/validate Version ^2.2 | — | — |
illuminate/support Version ^6.0|^7.0|^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.